Visitor III
November 13, 2024
Question
Threat Intel Management - Enable TAXII Server
- November 13, 2024
- 3 replies
- 2311 views
Hello,
I have enabled TAXII Server via Threat Intel Management and configured the TAXII on my FortiGate devices too. The Malicious entries are being synced to FortiGate configurations however facing few issues and need help on below:
1- We had a requirement to add additional picklist types for filehashes i.e. Vhash, SSDEEP, Authentihash for blocking. And added the values too in TIM. It got synced to FortiGate however shows invalid entries unlike other valid entries for Filehash MD5, SHA1. Please guide what is missing here.
2-For some FortiGate devices, Threat intel feeds are replicated to some FortiGate devices and are not replicated on some. Please guide what can be the issue and any logs or troubleshooting steps for the same.
